Compare commits

..

4 Commits

Author SHA1 Message Date
a72d556a36 added permission check to StockModule.getChildLocations
Signed-off-by: Stephan Richter <s.richter@srsoftware.de>
2026-02-12 08:41:12 +01:00
6e7bb08738 Merge branch 'feature/stock-item-link'
All checks were successful
Build Docker Image / Docker-Build (push) Successful in 2m34s
Build Docker Image / Clean-Registry (push) Successful in 2s
2026-02-12 08:24:21 +01:00
aaf33ffa8f implemented GUI update on cloning items
Signed-off-by: Stephan Richter <s.richter@srsoftware.de>
2026-02-10 23:48:10 +01:00
f4e85c870c implemented cloning of stock items. NEXT: update of GUI via message bus
Signed-off-by: Stephan Richter <s.richter@srsoftware.de>
2026-02-10 08:45:00 +01:00
10 changed files with 152 additions and 29 deletions

View File

@@ -49,11 +49,11 @@ public class MessageApi extends BaseHandler{
if (++counter > 300) counter = sendBeacon(addr,stream); if (++counter > 300) counter = sendBeacon(addr,stream);
} else { } else {
var event = eventQueue.removeFirst(); var event = eventQueue.removeFirst();
//if (event.isIntendedFor(user.get())) { if (event.isIntendedFor(user.get())) {
LOG.log(DEBUG, "sending event to {0}", addr); LOG.log(DEBUG, "sending event to {0}", addr);
sendEvent(stream, event); sendEvent(stream, event);
counter = 0; counter = 0;
//} }
} }
} }
LOG.log(INFO,"{0} disconnected from event stream.",addr); LOG.log(INFO,"{0} disconnected from event stream.",addr);

View File

@@ -12,7 +12,7 @@ public class MessageBus {
private MessageBus(){} private MessageBus(){}
public void dispatch(Event event){ public void dispatch(Event<?> event){
new Thread(() -> { // TODO: use thread pool new Thread(() -> { // TODO: use thread pool
try { try {
Thread.sleep(100); Thread.sleep(100);

View File

@@ -0,0 +1,48 @@
/* © SRSoftware 2025 */
package de.srsoftware.umbrella.messagebus.events;
import static de.srsoftware.umbrella.core.constants.Field.*;
import static de.srsoftware.umbrella.core.model.Translatable.t;
import de.srsoftware.umbrella.core.ModuleRegistry;
import de.srsoftware.umbrella.core.api.Owner;
import de.srsoftware.umbrella.core.model.*;
import java.util.Collection;
import java.util.List;
public class ItemEvent extends Event<Item>{
public ItemEvent(UmbrellaUser initiator, String module, Item item, EventType type) {
super(initiator, module, item, type);
}
@Override
public Collection<UmbrellaUser> audience() {
Owner owner = payload().location().resolve().owner().resolve();
if (owner instanceof UmbrellaUser user) return List.of(user);
if (owner instanceof Company company) return ModuleRegistry.companyService().getMembers(company.id());
return List.of();
}
@Override
public Translatable describe() {
return switch (eventType()){
case CREATE -> describeCreate();
case null, default -> null;
};
}
private Translatable describeCreate() {
var loc = payload().location().resolve().name();
return t("{user} added \"{item}\" to \"{location}\"", USER,initiator().name(), ITEM, payload().name(), LOCATION, loc);
}
@Override
public Translatable subject() {
var loc = payload().location().resolve().name();
return switch (eventType()){
case CREATE -> t("A new item has been added to \"{location}\":",LOCATION,loc);
case null, default -> null;
};
}
}

View File

@@ -6,7 +6,9 @@ public class Path {
public static final String ADD = "add"; public static final String ADD = "add";
public static final String AVAILABLE = "available"; public static final String AVAILABLE = "available";
public static final String CSS = "css"; public static final String CSS = "css";
public static final String CLONE = "clone";
public static final String COMMON_TEMPLATES = "common_templates"; public static final String COMMON_TEMPLATES = "common_templates";
public static final String COMPANY = "company"; public static final String COMPANY = "company";
public static final String CONNECTED = "connected"; public static final String CONNECTED = "connected";

View File

@@ -552,7 +552,7 @@ public class DocumentApi extends BaseHandler implements DocumentService {
private boolean postToDocument(HttpExchange ex, de.srsoftware.tools.Path path, UmbrellaUser user, long docId) throws IOException, UmbrellaException { private boolean postToDocument(HttpExchange ex, de.srsoftware.tools.Path path, UmbrellaUser user, long docId) throws IOException, UmbrellaException {
var head = path.pop(); var head = path.pop();
return switch (head){ return switch (head){
case CLONE -> postCloneDoc(docId,ex,user); case Path.CLONE -> postCloneDoc(docId,ex,user);
case POSITION -> postDocumentPosition(docId,ex,user); case POSITION -> postDocumentPosition(docId,ex,user);
case PATH_SEND -> sendDocument(ex,path,user,docId); case PATH_SEND -> sendDocument(ex,path,user,docId);
case null, default -> super.doPost(path,ex); case null, default -> super.doPost(path,ex);

View File

@@ -1,11 +1,39 @@
<script> <script>
import { api, post } from '../../urls.svelte'; import { onDestroy, onMount } from 'svelte';
import { api, eventStream, post } from '../../urls.svelte';
import { error, yikes } from '../../warn.svelte'; import { error, yikes } from '../../warn.svelte';
import { t } from '../../translations.svelte'; import { t } from '../../translations.svelte';
let { items, selected = $bindable(null), location = null, drag_start = item => console.log({dragging:item}) } = $props(); let { items, selected = $bindable(null), location = null, drag_start = item => console.log({dragging:item}) } = $props();
let eventSource = null;
let newItem = $state({name:null, code: null}); let newItem = $state({name:null, code: null});
function handleCreateEvent(evt){
let json = JSON.parse(evt.data);
if (json.item.location.id == location.id){
items = [...items,json.item];
selected = json.item;
}
}
function handleEvent(evt,method){
console.log(evt,method);
}
function handleDeleteEvent(evt){
handleEvent(evt,'delete');
}
function handleUpdateEvent(evt){
handleEvent(evt,'update');
}
function load(){
try {
eventSource = eventStream(handleCreateEvent,handleUpdateEvent,handleDeleteEvent);
} catch (ignored) {}
}
async function saveNewItem(){ async function saveNewItem(){
newItem.location = location; newItem.location = location;
const url = api('stock/item'); const url = api('stock/item');
@@ -17,6 +45,12 @@
items = [...items, it]; items = [...items, it];
} else error(res); } else error(res);
} }
onDestroy(() => {
if (eventSource) eventSource.close();
});
onMount(load);
</script> </script>
<table> <table>
<thead> <thead>

View File

@@ -1,7 +1,7 @@
<script> <script>
import LineEditor from '../../Components/LineEditor.svelte'; import LineEditor from '../../Components/LineEditor.svelte';
import { onMount } from 'svelte'; import { onMount } from 'svelte';
import { api } from '../../urls.svelte'; import { api, patch, post } from '../../urls.svelte';
import { error, yikes } from '../../warn.svelte'; import { error, yikes } from '../../warn.svelte';
import { t } from '../../translations.svelte'; import { t } from '../../translations.svelte';
@@ -15,6 +15,15 @@
} }
}); });
async function doClone(ev){
let url = api('stock/clone');
let res = await post(url,{id:item.id});
if (res.ok){
let json = await res.json();
yikes(res);
} else error(res);
}
function byName(a,b){ function byName(a,b){
return a.name.localeCompare(b.name); return a.name.localeCompare(b.name);
} }
@@ -30,11 +39,7 @@
}, },
add_prop : add_prop add_prop : add_prop
} }
const res = await fetch(url,{ const res = await post(url,data);
credentials:'include',
method:'POST',
body:JSON.stringify(data)
});
if (res.ok){ if (res.ok){
const prop = await res.json(); const prop = await res.json();
const id = prop.id; const id = prop.id;
@@ -45,18 +50,14 @@
return false; return false;
} }
async function patch(key,newVal){ async function update(key,newVal){
const url = api('stock'); const url = api('stock');
const data = { const data = {
id : item.id, id : item.id,
owner : item.owner, owner : item.owner,
}; };
data[key] = newVal; data[key] = newVal;
const res = await fetch(url,{ const res = await patch(url,data);
credentials:'include',
method:'PATCH',
body:JSON.stringify(data)
});
if (res.ok){ if (res.ok){
yikes(); yikes();
return true; return true;
@@ -67,22 +68,23 @@
</script> </script>
{#if item} {#if item}
<LineEditor type="h3" editable={true} value={item.name} onSet={v => patch('name',v)} /> <LineEditor type="h3" editable={true} value={item.name} onSet={v => update('name',v)} />
Code: <LineEditor type="span" editable={true} value={item.code} onSet={v => patch('code',v)} /> <button class="clone symbol" title={t('clone')} onclick={doClone}></button>
<div> <div>
{@html item.description.rendered} {@html item.description.rendered}
</div> </div>
<table> <table>
<tbody> <tbody>
<tr> <tr>
<td>{t('ID')}</td>
<td>{item.id}</td>
</tr>
<tr>
<td>{t('Code')}:</td>
<td> <td>
{t('ID')} <LineEditor type="span" editable={true} value={item.code} onSet={v => update('code',v)} />
</td>
<td>
{item.id}
</td> </td>
</tr> </tr>
{#each item.properties.toSorted(byName) as prop} {#each item.properties.toSorted(byName) as prop}
<tr> <tr>
<td> <td>

View File

@@ -1,6 +1,7 @@
description = "Umbrella : Stock" description = "Umbrella : Stock"
dependencies{ dependencies{
implementation(project(":bus"))
implementation(project(":core")) implementation(project(":core"))
implementation("de.srsoftware:configuration.json:1.0.3") implementation("de.srsoftware:configuration.json:1.0.3")
} }

View File

@@ -14,6 +14,7 @@ import static de.srsoftware.umbrella.core.constants.Module.USER;
import static de.srsoftware.umbrella.core.constants.Path.*; import static de.srsoftware.umbrella.core.constants.Path.*;
import static de.srsoftware.umbrella.core.constants.Path.PROPERTY; import static de.srsoftware.umbrella.core.constants.Path.PROPERTY;
import static de.srsoftware.umbrella.core.exceptions.UmbrellaException.*; import static de.srsoftware.umbrella.core.exceptions.UmbrellaException.*;
import static de.srsoftware.umbrella.messagebus.MessageBus.messageBus;
import static de.srsoftware.umbrella.stock.Constants.*; import static de.srsoftware.umbrella.stock.Constants.*;
import static java.lang.System.Logger.Level.WARNING; import static java.lang.System.Logger.Level.WARNING;
import static java.util.Comparator.comparing; import static java.util.Comparator.comparing;
@@ -26,11 +27,14 @@ import de.srsoftware.umbrella.core.*;
import de.srsoftware.umbrella.core.api.Owner; import de.srsoftware.umbrella.core.api.Owner;
import de.srsoftware.umbrella.core.api.StockService; import de.srsoftware.umbrella.core.api.StockService;
import de.srsoftware.umbrella.core.constants.Field; import de.srsoftware.umbrella.core.constants.Field;
import de.srsoftware.umbrella.core.constants.Module;
import de.srsoftware.umbrella.core.constants.Path; import de.srsoftware.umbrella.core.constants.Path;
import de.srsoftware.umbrella.core.constants.Text; import de.srsoftware.umbrella.core.constants.Text;
import de.srsoftware.umbrella.core.exceptions.UmbrellaException; import de.srsoftware.umbrella.core.exceptions.UmbrellaException;
import de.srsoftware.umbrella.core.model.*; import de.srsoftware.umbrella.core.model.*;
import de.srsoftware.umbrella.core.model.Location; import de.srsoftware.umbrella.core.model.Location;
import de.srsoftware.umbrella.messagebus.events.Event;
import de.srsoftware.umbrella.messagebus.events.ItemEvent;
import java.io.IOException; import java.io.IOException;
import java.util.*; import java.util.*;
import org.json.JSONObject; import org.json.JSONObject;
@@ -208,6 +212,7 @@ public class StockModule extends BaseHandler implements StockService {
if (user.isEmpty()) return unauthorized(ex); if (user.isEmpty()) return unauthorized(ex);
var head = path.pop(); var head = path.pop();
return switch (head) { return switch (head) {
case Path.CLONE -> postClone(user.get(),ex);
case Path.ITEM -> postItem(user.get(), ex); case Path.ITEM -> postItem(user.get(), ex);
case LIST -> postItemList(user.get(), path, ex); case LIST -> postItemList(user.get(), path, ex);
case Path.LOCATION -> postLocation(user.get(),ex); case Path.LOCATION -> postLocation(user.get(),ex);
@@ -221,7 +226,8 @@ public class StockModule extends BaseHandler implements StockService {
} }
private boolean getChildLocations(UmbrellaUser user, long parentId, HttpExchange ex) throws IOException { private boolean getChildLocations(UmbrellaUser user, long parentId, HttpExchange ex) throws IOException {
LOG.log(WARNING,"No security check implemented for {0}.getChildLocations(user, parentId, ex)!",getClass().getSimpleName()); // TODO check, that user is allowed to request that location var owner = stockDb.loadLocation(parentId).owner();
if (!assigned(owner,user)) throw forbidden("You are not allowed to access items of {owner}", OWNER,owner);
return sendContent(ex, stockDb.listChildLocations(parentId).stream().sorted(comparing(l -> l.name().toLowerCase())).map(DbLocation::toMap)); return sendContent(ex, stockDb.listChildLocations(parentId).stream().sorted(comparing(l -> l.name().toLowerCase())).map(DbLocation::toMap));
} }
@@ -303,7 +309,7 @@ public class StockModule extends BaseHandler implements StockService {
var json = json(ex); var json = json(ex);
if (!(json.get(ID) instanceof Number id)) throw missingField(ID); if (!(json.get(ID) instanceof Number id)) throw missingField(ID);
json.remove(ID); json.remove(ID);
LOG.log(WARNING,"Missing permission check in StockModule.patchItem()!");
var item = stockDb.loadItem(id.longValue()); var item = stockDb.loadItem(id.longValue());
item.patch(json); item.patch(json);
return sendContent(ex,stockDb.save(item)); return sendContent(ex,stockDb.save(item));
@@ -354,6 +360,23 @@ public class StockModule extends BaseHandler implements StockService {
return sendContent(ex,location); return sendContent(ex,location);
} }
private boolean postClone(UmbrellaUser user, HttpExchange ex) throws IOException {
var json = json(ex);
if (!json.has(ID))throw missingField(ID);
if (!(json.get(ID) instanceof Number num)) throw invalidField(ID,Text.NUMBER);
long itemId = num.longValue();
var item = stockDb.loadItem(itemId);
stockDb.loadProperties(item);
var location = item.location().resolve();
var owner = location.owner().resolve();
if (!assigned(owner,user)) throw forbidden("You are not allowed to add items to \"{location}\"!", Text.LOCATION,location.name());
var newItem = new Item(0,owner,0,location,item.code(),item.name(),item.description());
for (var property : item.properties()) newItem.properties().add(property);
newItem = stockDb.save(newItem);
messageBus().dispatch(new ItemEvent(user, Module.STOCK, newItem, Event.EventType.CREATE));
return sendContent(ex,newItem);
}
private boolean postItem(UmbrellaUser user, HttpExchange ex) throws IOException { private boolean postItem(UmbrellaUser user, HttpExchange ex) throws IOException {
var json = json(ex); var json = json(ex);
if (!json.has(NAME) || !(json.get(NAME) instanceof String name)) throw missingField(NAME); if (!json.has(NAME) || !(json.get(NAME) instanceof String name)) throw missingField(NAME);
@@ -363,8 +386,10 @@ public class StockModule extends BaseHandler implements StockService {
var location = stockDb.loadLocation(locationData.getLong(ID)); var location = stockDb.loadLocation(locationData.getLong(ID));
var owner = location.owner().resolve(); var owner = location.owner().resolve();
if (!assigned(owner,user)) throw forbidden("You are not allowed to add items to {location}!", Field.LOCATION,location); if (!assigned(owner,user)) throw forbidden("You are not allowed to add items to {location}!", Field.LOCATION,location);
var newItem = new Item(0,owner,0,location,code,name,description); var newItem = stockDb.save(new Item(0,owner,0,location,code,name,description));
return sendContent(ex,stockDb.save(newItem)); messageBus().dispatch(new ItemEvent(user, Module.STOCK, newItem, Event.EventType.CREATE));
return sendContent(ex,newItem);
} }
private boolean postItemList(UmbrellaUser user, de.srsoftware.tools.Path path, HttpExchange ex) throws IOException { private boolean postItemList(UmbrellaUser user, de.srsoftware.tools.Path path, HttpExchange ex) throws IOException {
@@ -413,6 +438,7 @@ public class StockModule extends BaseHandler implements StockService {
if (!(itemData.get(ID) instanceof Number itemId)) throw missingField(ID); if (!(itemData.get(ID) instanceof Number itemId)) throw missingField(ID);
if (!(json.get("add_prop") instanceof JSONObject propData)) throw missingField("add_prop"); if (!(json.get("add_prop") instanceof JSONObject propData)) throw missingField("add_prop");
if (!propData.has(VALUE)) throw missingField(VALUE); if (!propData.has(VALUE)) throw missingField(VALUE);
LOG.log(WARNING,"Missing permission check in StockModule.postProperty()!");
var value = propData.get(VALUE); var value = propData.get(VALUE);
if (value == null) throw missingField(VALUE); if (value == null) throw missingField(VALUE);

View File

@@ -476,6 +476,16 @@ table{
bottom: 0; bottom: 0;
} }
.properties{
position: relative;
}
.properties .clone{
position: absolute;
right: 10px;
top: 40px;
}
.version > a{ .version > a{
padding: 5px; padding: 5px;
} }